7.5
CVSSv2

CVE-2012-6612

Published: 07/12/2013 Updated: 08/03/2014
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The (1) UpdateRequestHandler for XSLT or (2) XPathEntityProcessor in Apache Solr prior to 4.1 allows remote malicious users to have an unspecified impact via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, different vectors than CVE-2013-6407.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache solr

apache solr 4.0.0

Vendor Advisories

Debian Bug report logs - #731113 lucene-solr: CVE-2013-6397 CVE-2013-6407 CVE-2013-6408 Package: lucene-solr; Maintainer for lucene-solr is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Mon, 2 Dec 2013 09:06:02 UTC Severity: grave Tags: ...